57.620 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.620 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2020-5937 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager On BIG-IP AFM 15.1.0-15.1.0.5, the Traffic Management Microkernel (TMM) may produce a core file while processing layer 4 (L4) behavioral denial-of-service (DoS) traffic. | 1,3% | — |
| CVE-2018-0269 | MED 4.3 | cisco digital_network_architecture_center A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauthenticated, remote attacker to communicate with the Kong API server without restriction. The vulnerability is due to an overly permissive Cro | 1,3% | — |
| CVE-2017-9488 | HIGH 8.8 | cisco dpc3939_firmware The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) and DPC3941T (firmware version DPC3941_2.5s3_PROD_sey) devices allows remote attackers to access the web UI by establishing a session to the wan0 WAN IPv6 addre | 1,3% | — |
| CVE-2003-1004 | MED 5.0 | cisco pix_firewall Cisco PIX firewall 6.2.x through 6.2.3, when configured as a VPN Client, allows remote attackers to cause a denial of service (dropped IPSec tunnel connection) via an IKE Phase I negotiation request to the outside interface of the firewall. | 1,3% | — |
| CVE-2003-1002 | MED 5.0 | cisco catalyst_6500 Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set. | 1,3% | — |
| CVE-2023-23838 | MED 6.5 | solarwinds database_performance_analyzer Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. | 1,3% | — |
| CVE-2022-45470 | HIGH 7.5 | apache hama missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect these issues to be fixed. | 1,3% | — |
| CVE-2022-23443 | HIGH 7.5 | fortinet fortisoar An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests. | 1,3% | — |
| CVE-2022-20748 | MED 5.3 | cisco secure_firewall_threat_defense A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to insufficien | 1,3% | — |
| CVE-2021-28927 | HIGH 7.8 | libretro retroarch The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platform_win32.c via the accessibility_speak_windows function, which allows attackers who have write access on filesystems that are used by RetroAr | 1,3% | — |
| CVE-2012-0362 | MED 4.3 | cisco ios The extended ACL functionality in Cisco IOS 12.2(58)SE2 and 15.0(1)SE discards all lines that end with a log or time keyword, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending network traffic, aka Bu | 1,3% | — |
| CVE-2007-6053 | HIGH 9.3 | ibm db2_universal_database IBM DB2 UDB 9.1 before Fixpak 4 does not properly handle use of large numbers of file descriptors, which might allow attackers to have an unknown impact involving "memory corruption." NOTE: the vendor description of this issue is too vague to be certain that i | 1,3% | — |
| CVE-2007-5547 | MED 4.3 | cisco ios Cross-site scripting (XSS) vulnerability in Cisco IOS allows remote attackers to inject arbitrary web script or HTML, and execute IOS commands, via unspecified vectors, aka PSIRT-2022590358. NOTE: as of 20071016, the only disclosure is a vague pre-advisory wi | 1,3% | — |
| CVE-2023-36793 | HIGH 7.8 | microsoft .net Visual Studio Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2023-36792 | HIGH 7.8 | microsoft .net Visual Studio Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2021-39534 | HIGH 8.8 | juniper libslax An issue was discovered in libslax through v0.22.1. slaxIsCommentStart() in slaxlexer.c has a heap-based buffer overflow. | 1,3% | — |
| CVE-2021-39533 | HIGH 8.8 | juniper libslax An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a heap-based buffer overflow. | 1,3% | — |
| CVE-2021-39531 | HIGH 8.8 | juniper libslax An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a stack-based buffer overflow. | 1,3% | — |
| CVE-2020-0981 | HIGH 8.8 | microsoft windows_10 A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the vulnerability could allow an application with a certain integrity level to execute code at a different integrity | 1,3% | — |
| CVE-2019-1941 | MED 6.1 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected dev | 1,3% | — |
| CVE-2019-1827 | MED 6.1 | cisco rv320_firmware A vulnerability in the Online Help web service of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the service. The vuln | 1,3% | — |
| CVE-2019-1668 | MED 6.1 | cisco socialminer A vulnerability in the chat feed feature of Cisco SocialMiner could allow an unauthenticated, remote attacker to perform cross-site scripting (XSS) attacks against a user of the web-based user interface of an affected system. This vulnerability is due to insuf | 1,3% | — |
| CVE-2019-0065 | MED 5.3 | juniper junos On MX Series, when the SIP ALG is enabled, receipt of a certain malformed SIP packet may crash the MS-PIC component on MS-MIC or MS-MPC. By continuously sending a crafted SIP packet, an attacker can repeatedly bring down MS-PIC on MS-MIC/MS-MPC causing a susta | 1,3% | — |
| CVE-2018-15440 | MED 6.1 | cisco identity_services_engine_software A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. The v | 1,3% | — |
| CVE-2018-1261 | MED 4.7 | vmware spring_integration_zip Spring-integration-zip versions prior to 1.0.1 exposes an arbitrary file write vulnerability, which can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z) that holds path traversal filenames. So wh | 1,3% | — |